Bug 864576 (CVE-2014-2015) - VUL-1: CVE-2014-2015: freeradius-server: denial of service in rlm_pap hash processing
Summary: VUL-1: CVE-2014-2015: freeradius-server: denial of service in rlm_pap hash pr...
Status: RESOLVED FIXED
Alias: CVE-2014-2015
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Deadline: 2014-03-28
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/96331/
Whiteboard: maint:released:sle11-sp1:56499 maint...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-02-19 10:13 UTC by Victor Pereira
Modified: 2014-04-14 17:05 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-02-19 10:13:08 UTC
When freeradius verifies a password sent via RLM-PAP against an LDAP
server, some passwords will cause a stack overflow.

Some forms of SSHA, including forms that would be validated by servers
applying standard constraints on the user's password attribute, will
generate lengths over 64 bytes after hex-decoding.

References:
http://comments.gmane.org/gmane.comp.security.oss.general/12142
https://github.com/FreeRADIUS/freeradius-server/commit/0d606cfc29a.patch
https://github.com/FreeRADIUS/freeradius-server/commit/ff5147c9e5088c7.patch
http://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000610.html
https://github.com/FreeRADIUS/freeradius-server/commit/f610864d4c8f51d.patch
Comment 1 Swamp Workflow Management 2014-02-19 23:00:24 UTC
bugbot adjusting priority
Comment 3 Bernhard Wiedemann 2014-02-28 09:00:11 UTC
This is an autogenerated message for OBS integration:
This bug (864576) was mentioned in
https://build.opensuse.org/request/show/224190 13.1+12.3 / freeradius-server
Comment 4 Swamp Workflow Management 2014-02-28 09:38:05 UTC
The SWAMPID for this issue is 56488.
This issue was rated as low.
Please submit fixed packages until 2014-03-28.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 5 SMASH SMASH 2014-02-28 09:40:12 UTC
Affected packages:

SLE-11-SP3: freeradius-server
SLE-11-SP2: freeradius-server
Comment 11 Bernhard Wiedemann 2014-03-03 09:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (864576) was mentioned in
https://build.opensuse.org/request/show/224384 Factory / freeradius-server
Comment 13 Swamp Workflow Management 2014-03-08 14:04:26 UTC
openSUSE-SU-2014:0343-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 864576
CVE References: CVE-2014-2015
Sources used:
openSUSE 13.1 (src):    freeradius-server-2.2.0-7.4.1
openSUSE 12.3 (src):    freeradius-server-2.2.0-3.8.1
Comment 14 Swamp Workflow Management 2014-04-11 17:04:23 UTC
Update released for: freeradius-server, freeradius-server-debuginfo, freeradius-server-debugsource, freeradius-server-devel, freeradius-server-dialupadmin, freeradius-server-doc, freeradius-server-libs, freeradius-server-utils
Products:
SLE-DEBUGINFO 11-SP1-TERADATA (x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
Comment 15 Swamp Workflow Management 2014-04-14 10:05:29 UTC
Update released for: freeradius, freeradius-debuginfo, freeradius-devel, freeradius-dialupadmin
Products:
SLE-DEBUGINFO 10-SP3-TERADATA (x86_64)
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 16 Swamp Workflow Management 2014-04-14 13:54:21 UTC
Update released for: freeradius-server, freeradius-server-debuginfo, freeradius-server-debugsource, freeradius-server-devel, freeradius-server-dialupadmin, freeradius-server-doc, freeradius-server-libs, freeradius-server-utils
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SDK 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 17 Alexander Bergmann 2014-04-14 15:50:15 UTC
Fixed and released. Closing bug.
Comment 18 Swamp Workflow Management 2014-04-14 17:05:00 UTC
SUSE-SU-2014:0525-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 864576
CVE References: CVE-2014-2015
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    freeradius-server-2.1.1-7.18.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    freeradius-server-2.1.1-7.18.1
SUSE Linux Enterprise Server 11 SP3 (src):    freeradius-server-2.1.1-7.18.1